In this scenario, the Silver Peak appliances are not connected in the direct path of the network traffic. As a result, a network traffic redirection technique is used to forward traffic to the appliance.Web Cache Coordination Protocol (WCCP) supports the redirection of any TCP or UDP connections to appliances participating in WCCP Service Groups. The appliance intercepts only those packets that have been redirected to it. The appliance accelerates traffic flows that the Route Policy directs to a tunnel; all other traffic passes through the appliance unmodified.In the unlikely event that the appliance fails, WCCP on the WAN router removes the appliance from the WCCP Service Group and resumes forwarding traffic normally, according to its routing tables.At Site A, both the router and the participating appliance require a separate WCCP service group for each protocol used in the tunnel. So, if a tunnel uses both TCP and UDP, you must create a separate WCCP Service Group for each protocol (TCP and UDP) used in the A-to-B tunnel.
Note You don’t need a spare router port for this configuration. The Silver Peak appliance can be connected to an existing LAN segment and be multiple hops away.
• Appliance wan0 interface connects to network
• Do not connect lan0 interface
• Configure two WCCP v2 Service Groups on the Silver Peak appliance
(one for TCP and one for UDP)
• Configure two WCCP v2 Service Groups on the WAN router
(one for TCP and one for UDP)Fail-safe behavior should always be tested before production deployment by ensuring that traffic continues to flow in each of the following cases:
Cable the appliances into the network Connect each appliance’s wan0 interface to the network, reachable by the WAN router. Do not cable anything to an appliance’s lan0 interface. Silver Peak NX Series Appliances Operator’s Guide Access the Site A router’s command line interface (CLI) to:
• Configure an Access Control List (ACL) that redirects all traffic from the Site A subnet to the Site B subnet
• Configure two WCCP Service Groups — one for UDP, one for TCP
• Associate the ACL with the Service Group
• Enable WCCP on the appropriate router interface Access the Initial Config Wizard to assign Appliance IP and Management IP addresses for Site A’s appliance. Ensure that the cable connections are sound and you haven’t misconfigured any IP addresses.Do NOT proceed until you have verified connectivity. Create a tunnel and Route Policy on Site A’s appliance Run the Initial Config Wizard to set up Site B’s Silver Peak appliance in Bridge mode. Use this to ensure that the cable connections are sound and you haven’t misconfigured any IP addresses.Do NOT proceed until you have verified connectivity. To allow traffic to start flowing, admin up the tunnels on all sides. Verify the tunnel status and ensure that you’re able to access hosts through the tunnel.
Please send comments or suggestions regarding user documentation to techpubs@silver-peak.com. |